Vulnerability Bulletins |
DSA-3455 curl - security update |
|
| Affected software | Debian |
|
Isaac Boukris discovered that cURL, an URL transfer library, reusedNTLM-authenticated proxy connections without properly making sure thatthe connection was authenticated with the same credentials as set forthe new transfer. This could lead to HTTP requests being sent over theconnection authenticated as a different user. More info: https://www.debian.org/security/2016/dsa-3455 |
|






